Bug #79905 [Opn]: fopen() read-only streams in write mode doesn't fail

From: Date: Thu, 30 Jul 2020 12:56:20 +0000
Subject: Bug #79905 [Opn]: fopen() read-only streams in write mode doesn't fail
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228346@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79905&edit=1

 ID:                 79905
 Updated by:         cmb@php.net
 Reported by:        chokolatrix at gmail dot com
 Summary:            fopen() read-only streams in write mode doesn't fail
 Status:             Open
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   WINDOWS
 PHP Version:        7.4.8
 Block user comment: N
 Private report:     N

 New Comment:

The fact that opening the 'output', 'input', 'stdin',
'stderr' and
'fd' protocols completly ignores the given $mode[1], looks
actually wrong to me.

However, on Windows with IIS *F*CGI there is usually no stderr
(nor stdout for that matter); all communication with the Webserver
is done through a pipe.  The fact that PHP allows to open
php://stderr is certainly a bug in this case.

[1] <https://github.com/php/php-src/blob/php-7.4.8/ext/standard/php_fopen_wrapper.c#L215-L341>


Previous Comments:
------------------------------------------------------------------------
[2020-07-28 12:08:30] chokolatrix at gmail dot com

Related: https://bugs.php.net/bug.php?id=79166

------------------------------------------------------------------------
[2020-07-28 11:37:04] chokolatrix at gmail dot com

Description:
------------
PHP's fopen() should fail to:
- open read-only streams in write mode (STDIO in 'w' or other write modes)
- open write-only streams in read mode (STDOUT, STDERR etc. in 'r' or other read modes)

This was noticed because of Laravel's logging to stderr failing under Apache/2.4.29 (Win64)
mod_fcgid/2.3.9 and PHP 7.4.8 x64 NTS. 

There is possibly a bug with Apache and FastCGI exposing STDERR as non-writable (normally writes
STDERR to the error log), but Laravel logging code checks fopen() result being a stream before
writing to it.



Test script:
---------------
<?php
# c:\my-site\test.php

error_reporting(E_ALL);
ini_set('display_errors','On');

$fp = fopen('php://stdin', 'w');
var_dump($fp);

$fp = fopen('php://stderr', 'r');
var_dump($fp);

if ($fp) {
    // this then fails on Apache + FastCGI - might be an Apache + FCGI bug causing stderr not to be
writable
    fwrite($fp, "test");
} 


Expected result:
----------------
bool(false)
bool(false)


Actual result:
--------------
Notice: fwrite(): write of 4 bytes failed with errno=9 Bad file descriptor in test.php on line 7

resource(3) of type (stream)
resource(4) of type (stream)



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79905&edit=1


Thread (4 messages)

« previous php.bugs (#228346) next »